Buffalo (Shuiniu.exe) manual killing methods do not kill tools _ virus
Source: Internet
Author: User
This is a mobile storage can spread through the malicious virus, anti-virus software and download Trojan, and the virus used to inject virus code to Svchost.exe to protect itself, so that its discovery and deletion more difficult, because its main file name "ShuiNiu.exe", so called the virus "buffalo" Virus.
Quote:
File:ShuiNiu.exe
size:22069 bytes
Modified:2007 year November 5, 10:13:38
md5:1fa97a5e1766d6e668321838a6f3e536
Sha1:94388083fb1cdd3003fe13046bc817ab0f6d7fd0
Crc32:1d66bfab
Technical details:
1. After the virus runs, release the following copy:
%systemroot%\system32\shuiniu.exe
and write ShuiNiu.exe and autorun.inf to Removable Storage to achieve the purpose of transmission via U disk and other mobile storage
2. Call cmd, change the system time to 2005-10-31
3. Delete the following key
System\currentcontrolset\control\safeboot\minimalsystem\controlset001\control\safeboot\networksystem\ Controlset001\control\safeboot\minimal\
Break Safe Mode
4. Add image hijacking project hijack some security software to
7. Release ~dsniu! after virus operation. BAT deletes itself
8. After the action is also more sinister point of the virus, when the completion of these actions, the virus will start two svchost.exe, and its own virus code written into the two Svchost.exe process, after the ShuiNiu.exe exit process.
These two svchost.exe will monitor each other, and the ShuiNiu.exe can not be deleted at this time ...
9. The virus body has the text "Fuck You"
Manual Workaround:
Download Sreng and Xdelbox
1. Extract all files in Xdelbox compressed package into a folder, in the box next to add C:\windows\system32\ShuiNiu.exe
After you enter the next click on the Add button to be added to the file will appear in the big box below, and then select (Hold down ctrl) all the files in the big box below, right-click Click Reboot to delete immediately
2. After reboot, open Sreng
Start the Project registry delete the following items
<DsNiu><%systemroot%\system32\ShuiNiu.exe> []
and remove all red Ifeo hijacking items
Or in Sreng, system repair-advanced repair-fix security mode
The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion;
products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the
content of the page makes you feel confusing, please write us an email, we will handle the problem
within 5 days after receiving your email.
If you find any instances of plagiarism from the community, please send an email to:
info-contact@alibabacloud.com
and provide relevant evidence. A staff member will contact you within 5 working days.